facebook-pixel

Australian Data Breach Notification Scheme: Complete Compliance Guide

L
Lunyb Security Team
··10 min read

Since February 2018, Australian organisations have operated under one of the world's most consequential privacy accountability frameworks: the Notifiable Data Breaches (NDB) scheme. Introduced through amendments to the Privacy Act 1988, the scheme fundamentally changed how businesses must respond when personal information is compromised. With penalties now reaching up to AU$50 million per contravention following the 2022 reforms, understanding your obligations is no longer optional — it's a core business risk issue.

This guide walks Australian organisations through everything they need to know about the Notifiable Data Breaches scheme: who it applies to, what counts as an eligible breach, how quickly you must respond, and what practical steps you can take to stay compliant.

What Is the Australian Data Breach Notification Scheme?

The Notifiable Data Breaches (NDB) scheme is an Australian federal regulatory framework that requires entities covered by the Privacy Act 1988 to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when an "eligible data breach" occurs. It came into force on 22 February 2018 under Part IIIC of the Privacy Act.

The scheme's underlying purpose is straightforward: give individuals the information they need to protect themselves when their personal data has been exposed, and create accountability for organisations that handle Australian personal information.

Who the Scheme Applies To

The NDB scheme applies to all entities that already have obligations under the Australian Privacy Principles (APPs). This includes:

  • Australian Government agencies
  • Businesses and not-for-profits with an annual turnover of more than AU$3 million
  • Private sector health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Entities that trade in personal information
  • Some small businesses that opt in or are otherwise captured (e.g., contracted service providers to the Commonwealth)

Recent legislative reform proposals aim to remove the small business exemption entirely, meaning even smaller operators should be preparing for compliance obligations.

What Counts as an "Eligible Data Breach"?

An eligible data breach under the NDB scheme is a data breach that meets three specific criteria under section 26WE of the Privacy Act:

  1. There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by the entity.
  2. The breach is likely to result in serious harm to one or more individuals whose personal information was affected.
  3. The entity has not been able to prevent the likely risk of serious harm through remedial action.

What "Serious Harm" Means

Serious harm is not defined narrowly in the Act, but the OAIC interprets it broadly. It can include:

  • Financial or economic harm (fraud, identity theft, unauthorised transactions)
  • Physical harm or threats to safety (e.g., disclosure of a domestic violence victim's address)
  • Psychological or emotional harm
  • Reputational damage
  • Loss of employment or business opportunities
  • Discrimination or harassment

When assessing whether serious harm is "likely," organisations must consider factors such as the type and sensitivity of information involved, whether it was protected by security measures like encryption, the persons or types of persons who have obtained (or could obtain) the information, and the nature of the harm itself.

The 30-Day Assessment Rule

If an organisation suspects an eligible data breach may have occurred but isn't certain, the Privacy Act requires them to carry out a reasonable and expeditious assessment within 30 calendar days of becoming aware of the grounds for suspicion.

This three-stage assessment typically follows this structure:

  1. Initiate: Decide who is responsible for conducting the assessment and set a timeline.
  2. Investigate: Gather relevant facts about the incident — what information was involved, how, when, and who might be affected.
  3. Evaluate: Make an evidence-based decision about whether the incident meets the threshold of an eligible data breach.

If, at any point during the assessment, it becomes clear the breach is eligible, the notification obligation is triggered immediately — you don't get to use the remainder of the 30 days.

Notification Requirements: What, Who, and How

Once an organisation determines an eligible data breach has occurred, they must, as soon as practicable, prepare a statement and notify both the Commissioner and affected individuals.

What the Statement Must Contain

The notification statement, which must be lodged with the OAIC using its online Notifiable Data Breach form, must include:

  • The identity and contact details of the entity
  • A description of the eligible data breach
  • The kinds of information involved
  • Recommendations about steps individuals should take to respond

Options for Notifying Individuals

The Privacy Act sets out three options for notifying affected people:

OptionWhen to UseMethod
Option 1: Notify all individualsWhen you can identify everyone whose data was involvedDirect notification (email, phone, letter)
Option 2: Notify only at-risk individualsWhen you can identify only those at risk of serious harmDirect notification to that subset
Option 3: Publish a statementWhen neither of the above is practicablePublish on your website and take reasonable steps to publicise it

Penalties for Non-Compliance

The consequences for failing to comply with the NDB scheme were dramatically strengthened by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022. For serious or repeated interferences with privacy, penalties for body corporates can now reach the greater of:

  • AU$50 million; or
  • Three times the value of any benefit obtained through the misuse of information; or
  • 30% of the entity's adjusted turnover during the relevant period

Beyond financial penalties, the OAIC has enhanced powers to conduct assessments, issue infringement notices, and publish enforcement outcomes. Reputational damage from a poorly handled breach — like those seen with Optus, Medibank, and Latitude Financial — can far exceed the direct financial penalty.

How to Prepare: A Practical Compliance Checklist

Preparation is the single biggest factor determining whether a data breach becomes a manageable incident or a business-defining crisis. Here's a practical checklist for Australian organisations:

1. Know Your Data

You can't protect what you don't understand. Conduct a data mapping exercise to document:

  • What personal information you collect
  • Where it's stored (systems, geographies, third parties)
  • Who has access to it
  • How long you retain it

2. Build a Data Breach Response Plan

The OAIC strongly recommends every entity have a documented response plan. It should include:

  • Roles and responsibilities (incident lead, legal, comms, IT)
  • Escalation procedures
  • Assessment methodology aligned with the 30-day rule
  • Template notification statements
  • Communication protocols for the OAIC, affected individuals, and the public

3. Implement Reasonable Security Controls

APP 11 requires you to take "reasonable steps" to protect personal information. In practice this means multi-factor authentication, strong encryption at rest and in transit, patch management, access controls based on least-privilege, staff training, and vendor risk management.

For public-facing links and communications — such as marketing emails, campaign URLs, or customer-facing short links — using platforms with built-in security controls matters. Services like Lunyb provide link management with analytics and access controls that help reduce the risk of malicious redirects or unauthorised link tampering, which are common attack vectors in phishing-related breaches.

4. Train Your People

The overwhelming majority of Australian data breaches reported to the OAIC involve either malicious/criminal attacks (with phishing as the leading vector) or human error. Regular, role-specific training is the highest-leverage investment most organisations can make.

5. Test the Plan

Run tabletop exercises at least annually. Simulate scenarios such as ransomware, insider misuse, and vendor breaches so the response team knows what to do when the clock actually starts.

Common Types of Notifiable Breaches in Australia

According to OAIC's biannual Notifiable Data Breaches reports, the most frequently reported breach types include:

Breach SourceTypical ExamplesProportion (Approx.)
Malicious or criminal attackPhishing, ransomware, credential stuffing, hacking~65-70%
Human errorEmails sent to wrong recipient, misconfigured databases, lost devices~25-30%
System faultSoftware bugs exposing data, misconfigurations~3-5%

The health, finance, and government sectors consistently top the list for reported breaches — reflecting both the sensitivity of information they hold and the higher regulatory scrutiny they face.

How the NDB Scheme Compares with Global Frameworks

Australian organisations operating internationally often need to reconcile the NDB scheme with other frameworks. The following high-level comparison helps clarify key differences:

FeatureAustralia (NDB)EU (GDPR)UK (UK GDPR)
Notification triggerLikely serious harmRisk to rights and freedomsRisk to rights and freedoms
Regulator notification timelineAs soon as practicable (with 30-day assessment)72 hours72 hours
Individual notificationRequired if eligible breachRequired if high riskRequired if high risk
Maximum penaltyAU$50M / 30% turnover€20M / 4% global turnover£17.5M / 4% global turnover

Notably, the reform agenda outlined in the Australian Government's response to the Privacy Act Review Report signals Australia may move closer to GDPR-style tight notification timelines in the coming years.

Recent Developments and What's Next

The Australian privacy landscape is in the middle of the largest reform cycle since the Privacy Act's introduction. Key developments to watch include:

  • Tier-based civil penalty regime: A new mid-tier and low-tier structure allowing regulators to apply proportionate penalties for less serious contraventions.
  • Statutory tort of serious invasion of privacy: Now enacted, giving individuals a direct cause of action.
  • Removal of the small business exemption: Still under active consideration.
  • Enhanced children's privacy protections and a Children's Online Privacy Code.
  • Automated decision-making transparency requirements.

Organisations that treat compliance as an ongoing capability — rather than a one-time project — will be best positioned to adapt as these reforms roll out.

Reducing Breach Risk Through Everyday Security Hygiene

While enterprise-scale controls dominate compliance conversations, most breaches originate from mundane weaknesses: reused passwords, unpatched systems, phishing links clicked in a rush. Practical steps every organisation can take include:

  • Deploying phishing-resistant multi-factor authentication (like FIDO2/passkeys)
  • Using encrypted DNS resolvers on corporate networks
  • Vetting third-party tools that handle customer data or URLs
  • Enforcing HTTPS across all customer touchpoints
  • Auditing external-facing links and redirects regularly

For teams that share a lot of links with customers or partners, choosing a trusted link management platform is part of the security stack. You can compare options in our 2026 buyer's guide to URL shorteners or read our honest review of Lunyb to see how link security features stack up.

Frequently Asked Questions

Do I have to notify the OAIC of every data breach?

No. You only need to notify the OAIC and affected individuals if the incident meets the definition of an "eligible data breach" — meaning it involves personal information, is likely to result in serious harm, and cannot be remediated in time to prevent that harm. Minor incidents that don't meet this threshold should still be logged internally.

How quickly must I notify affected individuals?

The Privacy Act requires notification "as soon as practicable" after you determine an eligible data breach has occurred. There is no fixed hour or day count, but delays without a clear justification can attract regulator scrutiny. If you're still assessing whether a breach is eligible, you have up to 30 days to complete that assessment.

What if the breach happened at a third-party supplier?

If both your organisation and the supplier hold the affected personal information, either can discharge the notification obligation on behalf of both — but only one notification is needed. It's essential to have contractual clarity about breach notification responsibilities in your supplier agreements before an incident occurs.

Does the NDB scheme cover employee records?

Currently, the employee records exemption in the Privacy Act means most private sector employers are not required to notify under the NDB scheme for breaches involving current or former employee records used for employment purposes. However, this exemption is one of the areas under active review, and best practice is to notify affected employees regardless.

What are the biggest mistakes organisations make when responding to a breach?

The most common mistakes include: delaying assessment while waiting for perfect information, underestimating the scope of affected individuals, providing vague notifications that don't help people take protective action, failing to document the decision-making process, and not preserving forensic evidence. A pre-prepared response plan avoids most of these pitfalls.

Final Thoughts

The Notifiable Data Breaches scheme is more than a reporting obligation — it's a forcing function for better privacy governance across Australian organisations. With penalties climbing, regulator activity increasing, and further reforms on the horizon, the question is no longer whether your organisation will face a data breach, but how prepared you'll be when it happens. Investing in strong data governance, robust security controls, well-trained staff, and a tested response plan is the most reliable way to keep an incident from becoming a catastrophe.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles